chaienv@1.0.2
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17321
Ecosystem
npm
Summary
chaienv@1.0.2 is published as a small Chai environment helper, but its index.js unconditionally loads lib/config.js at require() time via const { config } = require('./lib/config'). lib/config.js is a 4,454,290-byte single-line module packed with obfuscator.io (RC4-decoded string array of roughly 26,000 entries), with no relation to the trivial no-op middleware the README advertises. The rest of lib/ ships verbatim pino internals (proto.js, multistream.js, levels.js, transport.js, worker.js, redaction.js, symbols.js) as decoys, the README CI badge and LICENSE point at github.com/pinojs/pino, and package.json bugs.url is jsonspack.com — none of which match the stated Chai-plugin purpose. Any consumer that imports this package executes the opaque 4.4MB blob on load; the package impersonates an unrelated well-known project's source tree to normalize the obfuscated sibling and bypass casual review.
Source: amazon-inspector (cbb73465123d4e732dae815badc8950b40e9447463c1fca697551ab3aa00e020)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.